File name:

MiniMeters v088 WiN-OSX-LiNUX.exe

Full analysis: https://app.any.run/tasks/bd994701-b26d-495c-88ba-914015354c5f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 04, 2023, 14:46:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

607590050EF8552DAED3067A5E2FD888

SHA1:

D33ACBB291C0E06A6A70B88767C0F71C40D0DC5F

SHA256:

37117BD93E3A162F4BFEEAD158F064AD075EC66589CB5DADE62DB4A90167A6D9

SSDEEP:

49152:+7HecD4dnbibBlXSGgbgjsbmLApne0Fop4R2uXB3iyLT/ex4XrL7P42DpJXWZn8w:m+cD4dnclgbgIkWnXFopLQ3iUrex4vkB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 1088)
      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 2300)
      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • setup.exe (PID: 3112)
      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3528)
    • The DLL Hijacking

      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
  • SUSPICIOUS

    • Reads the Internet Settings

      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • setup.tmp (PID: 2764)
      • msiexec.exe (PID: 3508)
    • Reads the Windows owner or organization settings

      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3528)
    • Searches for installed software

      • setup.tmp (PID: 2764)
    • Reads security settings of Internet Explorer

      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3508)
    • Reads settings of System Certificates

      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
    • Checks Windows Trust Settings

      • a1.exe (PID: 3428)
      • setup.tmp (PID: 2764)
      • msiexec.exe (PID: 3528)
      • msiexec.exe (PID: 3508)
    • Adds/modifies Windows certificates

      • a1.exe (PID: 3428)
    • Checks for Java to be installed

      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
    • Process requests binary or script from the Internet

      • setup.tmp (PID: 2764)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 3508)
    • Runs shell command (SCRIPT)

      • msiexec.exe (PID: 3508)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 3528)
  • INFO

    • Checks supported languages

      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 1088)
      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 3028)
      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • wmpnscfg.exe (PID: 2668)
      • setup.exe (PID: 3112)
      • setup.tmp (PID: 2764)
      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 2300)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3528)
      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
      • msiexec.exe (PID: 2640)
    • Reads the computer name

      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 3028)
      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • wmpnscfg.exe (PID: 2668)
      • setup.tmp (PID: 2764)
      • msiexec.exe (PID: 3528)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3508)
      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 2640)
    • Create files in a temporary directory

      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
      • setup.exe (PID: 3112)
      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 2300)
      • MiniMeters v088 WiN-OSX-LiNUX.exe (PID: 1088)
      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3528)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2668)
    • Creates files in the program directory

      • MiniMeters v088 WiN-OSX-LiNUX.tmp (PID: 600)
    • Checks proxy server information

      • setup.tmp (PID: 2764)
      • msiexec.exe (PID: 3508)
    • Reads Environment values

      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3508)
      • msiexec.exe (PID: 3932)
    • Creates files or folders in the user directory

      • setup.tmp (PID: 2764)
      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3508)
    • Reads the machine GUID from the registry

      • a1.exe (PID: 3428)
      • msiexec.exe (PID: 3528)
      • setup.tmp (PID: 2764)
      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
      • msiexec.exe (PID: 2640)
    • Process checks Powershell version

      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
    • Reads Microsoft Office registry keys

      • msiexec.exe (PID: 3932)
      • msiexec.exe (PID: 3508)
    • Application launched itself

      • msiexec.exe (PID: 3528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: MiniMeters v088 WiN-OSX-LiNUX Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: MiniMeters v088 WiN-OSX-LiNUX
ProductVersion: 1.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
14
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start minimeters v088 win-osx-linux.exe no specs minimeters v088 win-osx-linux.tmp no specs minimeters v088 win-osx-linux.exe minimeters v088 win-osx-linux.tmp wmpnscfg.exe no specs setup.exe no specs setup.tmp a1.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe taskkill.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
600"C:\Users\admin\AppData\Local\Temp\is-N0IB9.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmp" /SL5="$110156,832512,832512,C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exe" /SPAWNWND=$1001B6 /NOTIFYWND=$1B0142 C:\Users\admin\AppData\Local\Temp\is-N0IB9.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmp
MiniMeters v088 WiN-OSX-LiNUX.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-n0ib9.tmp\minimeters v088 win-osx-linux.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1088"C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exe" C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
MiniMeters v088 WiN-OSX-LiNUX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\minimeters v088 win-osx-linux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2300"C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exe" /SPAWNWND=$1001B6 /NOTIFYWND=$1B0142 C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exe
MiniMeters v088 WiN-OSX-LiNUX.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
MiniMeters v088 WiN-OSX-LiNUX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\minimeters v088 win-osx-linux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2640C:\Windows\system32\MsiExec.exe -Embedding 9524FC9DA3CE63C28045D7174E273ADC E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2668"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2764"C:\Users\admin\AppData\Local\Temp\is-DKT64.tmp\setup.tmp" /SL5="$60254,4289520,832512,C:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\setup.exe" C:\Users\admin\AppData\Local\Temp\is-DKT64.tmp\setup.tmp
setup.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-dkt64.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3028"C:\Users\admin\AppData\Local\Temp\is-V3TDH.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmp" /SL5="$1B0142,832512,832512,C:\Users\admin\AppData\Local\Temp\MiniMeters v088 WiN-OSX-LiNUX.exe" C:\Users\admin\AppData\Local\Temp\is-V3TDH.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmpMiniMeters v088 WiN-OSX-LiNUX.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-v3tdh.tmp\minimeters v088 win-osx-linux.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3112"C:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\setup.exe"C:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\setup.exeMiniMeters v088 WiN-OSX-LiNUX.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
MiniMeters v088 WiN-OSX-LiNUX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\is-snjp9.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3204"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\AW Manager\Windows Manager 1.0.0\install\97FDF62\Windows Manager - Postback Johan.msi" /qn CAMPAIGN=2666 AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\is-R5L7D.tmp\a1.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\is-R5L7D.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1701699054 /qn CAMPAIGN=""2666"" " CAMPAIGN="2666"C:\Windows\System32\msiexec.exea1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3428"C:\Users\admin\AppData\Local\Temp\is-R5L7D.tmp\a1.exe" /qn CAMPAIGN="2666"C:\Users\admin\AppData\Local\Temp\is-R5L7D.tmp\a1.exesetup.tmp
User:
admin
Company:
AW Manager
Integrity Level:
HIGH
Description:
Windows Manager Installer
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-r5l7d.tmp\a1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
18 860
Read events
18 766
Write events
89
Delete events
5

Modification events

(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2764) setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2764) setup.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3428) a1.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
32
Suspicious files
20
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\is-2BSM9.tmpexecutable
MD5:8A490203B325074BEB7077E0FA79404C
SHA256:5F4BBC9DD0A599D1B620CD15BAE572D9CAAFDD87626B611D5F19C922CE206E32
2300MiniMeters v088 WiN-OSX-LiNUX.exeC:\Users\admin\AppData\Local\Temp\is-N0IB9.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmpexecutable
MD5:2DCA2B685DE2074B30B7EF084372835E
SHA256:3C36236E4D309E1F240EC302F8F520F89F8CCA863EF54D0F07D9D9A97A09F675
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\erkutext
MD5:BFA6ADFF2316521D74A3C23A4A3D9691
SHA256:E5B2698C27B45FF91E1DC67415923FB0BFD59106C2D226D85E02008DA8834118
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\setup.exeexecutable
MD5:8A490203B325074BEB7077E0FA79404C
SHA256:5F4BBC9DD0A599D1B620CD15BAE572D9CAAFDD87626B611D5F19C922CE206E32
1088MiniMeters v088 WiN-OSX-LiNUX.exeC:\Users\admin\AppData\Local\Temp\is-V3TDH.tmp\MiniMeters v088 WiN-OSX-LiNUX.tmpexecutable
MD5:2DCA2B685DE2074B30B7EF084372835E
SHA256:3C36236E4D309E1F240EC302F8F520F89F8CCA863EF54D0F07D9D9A97A09F675
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\rettext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Program Files\MiniMeters v088 WiN-OSX-LiNUX\unins000.datbinary
MD5:9F0E8C8F6CF53CC480011561A80A490F
SHA256:15929158CEF8AFA448C49443C9E391FE68AB4294FE352A2A828FD0721D78AF9C
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Users\admin\AppData\Local\Temp\is-SNJP9.tmp\is-9QL91.tmptext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Program Files\MiniMeters v088 WiN-OSX-LiNUX\is-3J3M2.tmpexecutable
MD5:0C5AEDE3DC1F0E5E5F37172A12C11117
SHA256:6683D0DB03A53F6163F10D373297C67B4BB8ABF1C613D63E63CFA1D2994755AE
600MiniMeters v088 WiN-OSX-LiNUX.tmpC:\Program Files\MiniMeters v088 WiN-OSX-LiNUX\unins000.exeexecutable
MD5:0C5AEDE3DC1F0E5E5F37172A12C11117
SHA256:6683D0DB03A53F6163F10D373297C67B4BB8ABF1C613D63E63CFA1D2994755AE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
15
DNS requests
12
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
GET
200
188.114.97.3:80
http://restfork.website/wi.php?p=3942&t=47844776&title=TWluaU1ldGVycyB2MDg4IFdpTi1PU1gtTGlOVVg=&sub=2666&ps=656de5d0af72d
unknown
text
130 b
unknown
3508
msiexec.exe
GET
200
108.138.216.113:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.51 Kb
unknown
2764
setup.tmp
GET
200
159.223.29.40:80
http://kapetownlink.com/installer.exe
unknown
executable
4.51 Mb
unknown
3508
msiexec.exe
GET
200
108.138.216.113:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.39 Kb
unknown
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
GET
200
188.114.96.3:80
http://sidemark.xyz/pe/buildIN.php?sub=2666&source=3942&s1=47844776&title=TWluaU1ldGVycyB2MDg4IFdpTi1PU1gtTGlOVVg%3D&ti=1701701222
unknown
executable
4.90 Mb
unknown
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
GET
200
188.114.97.3:80
http://restfork.website/win.php
unknown
text
2 b
unknown
2764
setup.tmp
GET
200
184.24.77.206:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e9601a5c1f75fc20
unknown
compressed
4.66 Kb
unknown
2764
setup.tmp
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2764
setup.tmp
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
2764
setup.tmp
HEAD
200
159.223.29.40:80
http://kapetownlink.com/installer.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
188.114.97.3:80
restfork.website
CLOUDFLARENET
NL
unknown
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
188.114.96.3:80
restfork.website
CLOUDFLARENET
NL
unknown
2764
setup.tmp
172.67.198.151:443
false.apparelsilver.xyz
CLOUDFLARENET
US
unknown
2764
setup.tmp
184.24.77.206:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2764
setup.tmp
216.58.212.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2764
setup.tmp
159.223.29.40:80
kapetownlink.com
DIGITALOCEAN-ASN
DE
unknown

DNS requests

Domain
IP
Reputation
restfork.website
  • 188.114.97.3
  • 188.114.96.3
unknown
sidemark.xyz
  • 188.114.96.3
  • 188.114.97.3
unknown
false.apparelsilver.xyz
  • 172.67.198.151
  • 104.21.13.66
unknown
ctldl.windowsupdate.com
  • 184.24.77.206
  • 184.24.77.202
  • 184.24.77.193
whitelisted
ocsp.pki.goog
  • 216.58.212.131
whitelisted
kapetownlink.com
  • 159.223.29.40
unknown
collect.installeranalytics.com
  • 54.165.145.62
  • 54.165.38.232
unknown
o.ss2.us
  • 18.165.185.4
  • 18.165.185.206
  • 18.165.185.182
  • 18.165.185.120
whitelisted
ocsp.rootg2.amazontrust.com
  • 108.138.216.113
whitelisted
ocsp.rootca1.amazontrust.com
  • 108.138.216.113
shared

Threats

PID
Process
Class
Message
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Possibly Unwanted Program Detected
ET ADWARE_PUP Win32/TrojanDownloader Variant Activity (GET)
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
600
MiniMeters v088 WiN-OSX-LiNUX.tmp
Misc activity
ET INFO EXE - Served Attached HTTP
2764
setup.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2 ETPRO signatures available at the full report
No debug info